Hitachi Energy FACTS Control Platform (FCP) Multiple Vulnerabilities
First seen Sep 18, 2026 · Updated Sep 18, 2026 · CVSS 9.9
Hitachi Energy's FACTS Control Platform (FCP) with the GWS component is affected by five vulnerabilities, including a critical query injection flaw (CVSS 9.9) and a critical path traversal flaw (CVSS 9.9), along with authentication bypass, missing authentication, and open redirect issues. These affect FACTS-based grid stabilization equipment (SVC Light, STATCOM, series capacitors, synchronous condensers) deployed globally in the energy sector since 2020, and successful exploitation could compromise confidentiality, integrity, and availability of critical power grid control systems.
Technical Analysis
The advisory details five CVEs affecting Hitachi Energy FCP versions 3.4.0 through 4.1.1 when the GWS component is present: CVE-2024-4872 (CWE-943, CVSS 9.9) allows an authenticated attacker to inject code into persistent data via improper query validation; CVE-2024-3980 (CWE-22, CVSS 9.9) is a path traversal flaw enabling access/modification of critical system files; CVE-2024-3982 (CWE-294, CVSS 8.2) permits session hijacking via replay when session logging is enabled; CVE-2024-7940 (CWE-306, CVSS 8.3) exposes a service intended for local-only access to all network interfaces without authentication; and CVE-2024-7941 (CWE-601, CVSS 4.3) enables open-redirect-based phishing and credential theft. These vulnerabilities target OT/ICS equipment used in power grid stabilization (SVC Light, STATCOM, TCSC, SVC, SWC, hybrid synchronous condensers) and require network segmentation, firewalling, and VPN-based remote access as primary mitigations since no patch details are specified beyond general mitigation guidance. This is a pure OT/ICS vulnerability set with no direct connection to AI agent frameworks, LLM tool use, or RAG pipelines, and thus no plausible agent-relevant impact is present.
Affected Systems
Hitachi Energy FACTS Control Platform (FCP) versions 3.4.0, 3.7.0, 3.8.0, 3.10.0, 3.12.0, 3.14.0, 3.15.0, 4.0.0, 4.0.1, 4.1.0, 4.1.1 with GWS component deployed from 2020 onwards; product lines include SVC Light (STATCOM), Fixed Series Capacitor, Thyristor Controlled Series Capacitor, Static Var Compensator, Static Watt Compensator, and Hybrid Synchronous Condensers. Deployments without the GWS component are not affected.
Indicators of Compromise
- No specific indicators of compromise (hashes, IPs, domains) provided in this advisory; this is a vulnerability disclosure rather than an active exploitation report.
Remediation Steps
- 1
Apply vendor guidance
Consult Hitachi Energy security advisory 8DBD000229 for specific mitigation and remediation details applicable to each CVE.
- 2
Network segmentation
Isolate control system networks and remote devices behind firewalls, separating them from business networks and the internet.
- 3
Minimize exposure
Ensure control system devices, especially those with the GWS component, are not accessible from the internet and minimize the number of exposed network ports/services.
- 4
Secure remote access
Use VPNs for remote access where required, ensuring VPN software is kept up to date and endpoint devices are secured.
- 5
Restrict session logging
Keep session logging disabled by default and restrict administrator rights to prevent session hijacking via CVE-2024-3982.
- 6
Credential hygiene
Enforce strong password policies and monitor for authentication bypass attempts given CVE-2024-3982 and CVE-2024-7940.
- 7
Monitor and report
Follow internal incident response procedures and report suspected malicious activity to CISA for correlation with other incidents.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.